Category: Technology

GDPR compliance: what if you don’t comply as of 25 May 2018

GDPR COMPLIANCE has been the very hot topic of 2017 and will continue to grow in the next couple of months, as we are reaching 25 May 2018, the famous date where Regulation (EU) 2016/679 will apply to any controller and processor around the world falling into the scope of the Regulation. This topic will increase in importance with general awareness, the importance to “think privacy first” before any processing personal data occurs, and the increasing number privacy pros arising out around the globe advocating about privacy.

In this historic race for data protection compliance, the European Commission published a new website, with extensive guidance on that matter. This site is pretty intelligible, and designed in a simplified and easily accessible manner. It covers important areas of the GDPR indicating, among others:

including an infographic section with a summary of key areas that relate to the GDPR such as rights and duties, and consequences for non-compliance.

Now processors of personal data may have to demonstrate to the authorities that, and how, they comply with the Regulation (‘accountability’ principle).

__________________

WHAT TO EXPECT IF YOU DON’T COMPLY WITH THE GDPR?

On its new website, the Commission reminds the 4 steps process before a supervisory authority may impose an administrative fine (art. 83 of the GDPR) on businesses or organizations for non-compliance. These steps are:

(1) WARNING ⇨ (2) REPRIMAND ⇨ (3) SUSPENSION OF DATA PROCESSING ⇨ (4) FINES

and according to the Regulation, sanctions shall “in each individual case be effective, proportionate and dissuasive ” (art. 83 § 1 GDPR). Therefore, the fine regime allows a supervisory authority to impose a fine in addition to other measures, being (among others):

  • warnings (art. 58 (2) (a) and recital 150 of the GDPR);
  • withdrawal of certifications (art. 58 (2) (h) of the GDPR); or
  • suspension of data flows (art. 58 (2) (j) and 83 (5) (e) of the GDPR).

__________________

WHAT DOES ARTICLE 29 WP SAY ABOUT FINES UNDER THE GDPR?

The Article 29 Working Party (‘A29WP’) just updated its 253rd document called “Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679” (wp253). This document contains more details on the fine regime and how controller should behave to avoid fines.

The guidelines explains that warnings may already be given to controllers when processing operations are likely to infringe provisions of the Regulation. This means that warnings may be used as a preventive measure against a potential infringement (foot note, page 5 of wp253). Reprimand can, in some cases, replace a fine (page 9 of the guidelines), etc. In addition to this, the A29WP adds an interesting statement about the balance between imposing corrective measures with or without fines:

Fines are an important tool that supervisory authorities should use in appropriate circumstances. The supervisory authorities are encouraged to use a considered and balanced approach in their use of corrective measures, in order to achieve both an effective and dissuasive as well as a proportionate reaction to the breach. The point is to not qualify the fines as last resort, nor to shy away from issuing fines, but on the other hand not to use them in such a way which would devalue their effectiveness as a tool“.

The message is pretty clear, the supervisory authority shall ensure effectiveness through finding the right balance between fines, or measures, or both. Still, fines should not be “devalued” meaning, that a too nice fine may encourage controllers and processors to continue doing business without ensuring compliance.

You can access the guidelines on administrative fines here.

__________________

AUTHORITIES WILL NOT FINE EVERYONE AS OF 25 MAY 2018

It has become popular to hear and read from many people and consulting firms coming out of nowhere, shouting on social media and the internet, that the end of the world is going to happen in May 2018, should you be non-compliant. The reality is a bit more complex, and such statement isn’t true. It is true that after 25 May, there will be no more deadline for GDPR readiness, so sanctions may potentially be quite heavy when a controller is being audited, questionned by an authority or if an individual lodges a complaint against the controller. But this may only happen after the authority performs an assessment of the situation, starting with exchanges of communications, then maybe an audit if a data subject submitting a complaint for an infringement of their rights, or if one claims a the controller is breaching the law. You’d better be working on your GPDR readiness if you are subject to the Regulation and haven’t started yet. But it seems necessary to remind some basic considerations that are a bit less scaremongering on the sanction regime and compliance readiness, just to name a few:

  • Fines are not going to rain on data controllers as of 26 May 2018. This is a myth designed by hungry newly created consulting firms using fear as a marketing tool to sell their GDPR-related services. mid- to large organisations that are aware do not get trapped, but smaller may.
  • An authority will not issue a fine before having found evidence and probably warned the processor of personal data (controllers and to some extent processors) that there is, in their opinion, a breach of the law. It means that the process would require to conduct investigations , including audit of, or by, the controller, its retailers, suppliers or business partners, but also interpreting the GDPR, which is not easy.
  • According to UK ICO Steve Eckersley, “some investigations take 8-12 months to complete”. So it wil take some time. Taking the example of the UK, Steve Eckerley also mentions that “the ICO is now recruiting an additional 100-150 people to work on GDPR aspects and cyber security” predicting that the ICO will receive “30,000 breach notifications a year“. This is not a meaningless number.
  • Authorities are, and will remain, very busy to create their own team, support controllers in providing them guidance and support, help them interpreting the Regulation, implement exceptions to the GDPR into their own local laws (if they chose to do so), examine how to deal with breach notifications, work on DPIA submissions, etc. So the top priority is not to sanction everyone, but more to get ready for having the right staff to support this massive change in the regulatory landscape. GDPR may be a huge project not only for those who process personal data, but every stakeholders, including authorities pressured by the Commission for their own readiness. Being busy, does not mean that no sanction will occur. My sense is that there will be sanctions, but not immediately as everyone will be in a rush.
  • Regulation (UE) 2016/679 does not indicate fines as the first, nor the last measure if failing to comply with the law. In theory, a supervisory authority would warn the controller before a infringement of the law, where it is likely to occur. When a GDPR audit will occur in less clear cases, there will be room for dialogue and exchanges between authorities, legal counsels, appointed DPOs, outside counsels, data processors and other players of this privacy eco-system. It will also be interesting to see if the level of complaints issued by individuals will increase in the future, or if GDPR compliance will build more trust. Some people tend to forget that the GDPR is a formidable opportunity for organizations to advertise their good behavior and willingness to listen to the clients’ needs and respect their rights.
  • Compliance shall be maintained and monitored over time. GDPR compliance is not a one-shot project. It becomes a new behavior for companies vis-à-vis their clients and their business partners and it has to be included in the organisation’s processes. This will continue for as long as the Regulation remains in force, which means that a fine may occur much later. Your organization may be GDPR ready for 25 May 2018, but might not be any more if compliance is not maintained over time.
  • (edit) More than 70 provisions of the GDPR offer room for EU Member States to deviate from the Regulation. This means knowing the GDPR as a general law is not sufficient, and there will be different approaches depending on the countries. Germany being the first country to adopt its own adaptation of the GDPR in its local data protection law. You can access links on another article of this blog to track Member States’ readiness and deviations from the GDPR. As all the provisions of the Regulation are not self-explanatory and contain many provisons subject to interpretation, compliance with the GDPR remains a case-by-case assessment and will be subject to interpretation. As mentioned in this article, it could take around 10 years “before the GDPR might be considered a mature piece of legislation that is well understood“.

__________________

OTHER THREATS AND RISKS THAN FINES

Data processors of personal data (controllers and processors) should not only fear fines. A fine may just constitute an additional bad taste to an already too salted menu.

Personal data processors should take into consideration other risks or threats to their business as a result of GDPR non-compliance than just fines. Here are just a few examples that demonstrate how non-compliance may impact your organization and potentially your business as a whole:

  • reputational damage, financial and customer losses after an incident. Notifications of cybersecurity incidents to the individuals, when a breach is “likely to result in a likely to result in a high risk to the rights and freedoms of natural persons” (art. 34 (1) GDPR), reputational dammage causing loss of business opportunities, loss of customers, potential contractual liabilities, breach of contract, (just to name a few), may be much more damaging than a fine. If you read the news, you probably heard about the Talk-Talk disaster, where the unprepared spokesperson of Talk-Talk gave the worst signal ever to their customers when making a public statement about a data breach incident.
  • business discontinuity and costs recovery due to an incident. Not only a cybersecurity incident may cause the organization to stop being able to conduct its regular business and have reputational consequences on the market, but it will require to spend a lot of money to conduct investigations, fixing the issue, changing the processes where necessary, put in place stronger measures to prevent further incident, etc. A cybersecurity incident does not mean you are in breach of the GDPR, but with the increasing amount of personal data processed through connected networks, it is likely that a breach will also concern personal data of natural persons, which is regulated by the GDPR. This is where putting in place appropriate technical and organizational measures (which I call “ATOM“) plays a crucial role. In the most optimistic scenario, a well equiped and prepared company may not even require to inform the authorities, nor the individuals. In any case, it remains crucial to discuss and implement a cybersecurity preparedness plan and an incident response plan with the relevant people on a senior level.
  • suspension of data flows. While a cybersecurity incident may cause business discontinuity for a relative short period of time, an authority may impose a suspension of data flows. Despite the practical aspects of how an authority may enforce such measure, this might be damaging to the company if there is a business need to process the personal data.
  • competitors taking market share. This is a fear that some organizations should think about if they think non-compliance with EU privacy laws are just an academical topic. This is also where the GDPR is a great opportunity.
  • long-term ability to do business affected. Suspension of data flows may not be a common sanction given by an authority. However, non-compliance may prevent organizations to continue doing business with EU clients and cease to be competitive, losing market share.
  • loss of customer confidence.
  • staff losses and senior executive resignations.
  • allocation of an extra budget on security, data protection, restructuring, new roles and internal audits.
  • etc.

While NOT all organizations around the world falling into the scope of the GDPR will become GDPR compliant as of 25 May 2018, businesses and organizations processing personal data creating particular risks for the data subjects will be in the focus of the authorities. The so-called “Lex Facebook” will motivate authorities to focus on large companies such as the GAFAM and BATX, but also on their providers.

As long as your organization can demonstrate that GDPR readiness is on the top list of priorities and that working hard to achieve full compliance, you may be on the road to safety.

Be prepared, but not scared. Make the GDPR an opportunity, not a blocking point. Don’t fear fines, collaborate, remain transparent, prepare to demonstrate that you are working on compliance and that it is a priority for you. And if you need advice, then hire a specialized law firm.

__________________

By Gabriel Avigdor | NTIC.ch

Abilify connected pill: ethics and privacy aspects of Personal Health Monitoring

ABILIFY MYCITE: A FIRST FDA APPROVAL FOR mHEALTH AND CONNECTED MEDICAL DEVICES

On 13 November 2017, we have probably reached a historical new step in digital health (and mHealth) with this market approval from the FDA for “Abilify MyCite“, the first digital tracking-pill which sends data to your doctor. This connected pill is used to track whether patients sufferring from schizophrenia, bipolar I disorder, and depression have taken their medication, which is used for Personal Health Monitoring (‘PHM‘).

As mentionned by Pharmacytimes:

the approval of the pill and the sensor together represents a first for the FDA

even if the sensor itself that is used along with aripiprazole (substance used for patient suffering from schizophrenia) was first cleared for use by the FDA in 2012. As secondary or side effects, the clinical trials revealed adverse events such as nausea, vomiting, constipation, headache, dizziness, uncontrollable limb and body movements (akathisia), anxiety, insomnia, and restlessness. However, the common adverse events associated with the sensor were related to the patch, and were predominantly skin irritation.

Find more information on the website of the FDA.

________________________________

TECHNOLOGY AND FUNCTIONALITIES – How it works

On the technology side, the sensor embedded into the Ability MyCite pill syncs with a smartphone and sends an alert to the patient’s smartphone. The doctor receives also a notification through the App when the medication is ingested via a patch that is worn on the surface of the skin of the patient. If the patient shares its data with his practitioner, the latter has the ability to monitor whether the patient has ingested properly. According to the US TV channel PBS, researchers are also trying to manufacture ePills that collect and process other body-related data by monitoring internal heat of the body for several days long.

________________________________

TECHNICAL ASPECTS OF THE DEVICE

According to LiveScience, the technical aspects are as follows:

“It’s a partial power source, “the patient becomes the battery”. The pill integrates a silicon chip with a logic circuit and contains copper and magnesium.  The chip’s logic circuit makes a small modulated current — a graph of the current levels would look like a sine wave. Since the human body is conductive, the wearable sensor can pick up the changes. The modulated current can encode ones and zeroes, similar to an FM signal. “It works in a similar way as an EKG,” or electrocardiogram. These machines pick up on changes in electrical current in the body to monitor heartbeats. The wearable sensor does the same thing, though the current is smaller.” The pill is designed to work for only about 3 minutes. That’s just enough time for it to send a signal to the wearable sensor that it should wake up and start gathering data. That saves battery power and allows the wearable sensor to work for a week at a time.

The patch and sensor is manufactured by the company Proteus Digital Health and aripiprazole marketed by Otsuka Pharmaceutical.

________________________________

ETHICS AND LEGAL ISSUES

PATIENT MONITORING AND REDUCING HEALTH COSTS

Personal Health Monitoring (‘PHM ) contains at least two major advantages.

MEDICAL COMPLIANCE – being the “consistency and accuracy with which someone follows the regimen prescribed by a physician or other health professional“. In the context of mental disability, the physician must ensure that the patient suffering from a mental disorder takes the prescribed medication on a regular basis. This may be particularly interesting for patients who may find themselves incapable of making a proper judgement (such as elder people). In the USA, a study from the National center for biotechnology information showed that “an estimated 50% of those who respond well to medications are nonadherent to their treatment regime“. Therefore, medical compliance is also a important challenge for patients who are suffering from a mental illness; and

HEALTHCARE COSTS – which could be reduced if more patients would take their pill properly. Consequences are both medical and financial. When a patient do not or, forgets to, take a pill, or do not follow the treatment as prescribed, his/her health may be worsened and this person may require treatment adjustment, more medicine, another hospitalisation or even a further surgery should there be a need to. In particular, this article indicates that the “loss that the taxpayer incurs when patients fail to take their medication, the cost of which is assumed to be at least $100 billion. According to an American report, these numbers could even be between $100 et $300 billion.

*  *  *
TECHNOLOGICAL ADVANCEMENT: YES.  BUT AT WHAT COST AND
TO WHAT EXTENT DOES THIS REMAIN A PROGRESS?

Although such technological advancement (connected pill to track patient’s medical compliance) is remarkable for healthcare costs reduction, not everybody agrees to it, especially within the medical profession. Moreover, it is legitimate to ask to what extent such technology can constitute a practical improvement, not just a scientific progress.

What value does this progress add for patients, the healthcare system and the society in general? What does it improve, is it better than before? If yes, how and what are the bad sides of it? What is the balance between the bad and good sides of this? Will the benefits for the patient override financial benefits?

Some people already rose their voice and expressed reluctance to Personal Health Monitoring (‘PHM’), which scientists have already looked into and published on this complex topic. (see additional notes on that topic at the end of this article).

Altough a few have called this practice “medical Big Brother (or biomedical Big Brother according to the New York Times), PHM raises a number of ethical questions, which can lead to at least 8 key  points and interrogations:

1. Privacy – for personal health monitoring, two types of privacy aspects can emerge, which are personal privacy and data privacy. This also relates to risk of interference in the private life of the patient by collecting and processing health (sensitive or even biometric) patient data. Is such data processing in compliance with explicit consent of the patient, who may not able to make a proper judgement?  This article describes very well some privacy aspects  that personal health monitoring are raising.

2. Visibility or  obstrusiveness – Visibility appears to refer to “the degree to which a PHM device is noticeable by the user and other individuals, both at home and in public“. In accepting the use of tracking devices for dementia patients, cognitively intact older adults identified ease of use, size and weight as important in accepting a tracking technology. One consider the patient differently, being seen as an ill human being. This may create a risk of discrimination by the society and the person might be more vulnerable;

3. (over)Medicalization – the devices have the effect of reminding the user or occupants of a medical condition in a non-medical environment. The home could be turned into a medical environment or “de facto intensive care unit” as well as creating stigmatization linked to the fact that the person feels under surveillance;

4. Social isolation – the patient monitored will reduce or cease going to the hospital or to see the physician for regular check-ups. Therefore, this could increase patient’s loneliness and social isolation with psychological and medical consequences with a lack of motivation and reduction of the mentality;

5. Autonomy what room remains to the patient with PHM to decide how to take the pill or not? What if the patient wishes to stop taking the pill, for good reasons? Where are we talking about pressure on the patient will?

6. Shame et identity – what consequences could there be on the personality of the patient, who may be perceived by the society as marginal human being, in particular when the treatment is visible?

7. Providing healthcare – with remote care, to what extent does this improve or reduce its effectiveness, especially when the patient does not move him/herself anymore? Is this an efficient manner to treat a patient, shall this remain the exclusive way of doing it or should we combine it with physical appointments?

8. Security and reliability of the technology. This element is obviously central for both privacy and health reasons.

Do these aspects reduce or delete the patient’s responsibility or does it create an over-responsibility? With or without benefits?

How about from an insurance point of view if the patient do not takes the pill while he/she is being monitored with or without worsening of his/her health? Suspension, reduction, cessation of the payment by the insurance or the medical measures? To what extent can the insurance have access to such information or personal health-related data?

________________________________

A PRIVACY PERSPECTIVE?

As this article pointed out, despite huge costs reductions (around 100 billion) and health benefits of this mHealth technology for the healthcare system and patients, patient’s privacy is an area of concern which is even more related to medtech technologies with Big data and IoT (Internet of Things) in the healthcare sector. Combined with the patch worn by the patient, the sensors that are embedded into the pill may provide far more data about the patient than just taking a pill or not.  The device may be used in a way to gather data from the patient’s body, such as the heart rate, how much the patient sleeps, how fit the patient is, etc.

The major concern is the misuse of such sensitive data, which could be used by corporations or government to collect more personal and biometric information about citizens that they had consented to revealing. Furthermore, since the technology has only recently come into the public domain, very few regulations exist to police it, says this article. Misuse for marketing purposes, is one thing. Data breach, criminal intents, or cyberattack on the device itself are another thing with severe consequences for both patients’ health, privacy and reputations of tech and pharma organizations. Further, another study explains that it appears impossible to obtain informed consent from recipients of PHM because full understanding of the implications of using PHM cannot be gained without actually using the technology. Therefore, using the technology without informed consent, may be considered as illegal processing, which creates a vicious circle. This article suggests that piloting methods such as storytelling and prototyping may present a possible solution to this problem and avoid collecting personal data without the proper legal basis for processing.

________________________________

PRIVACY AND INFORMATION SECURITY 

From an EU and Swiss perspective, health-related data (health or biometric) is considered as a special category of personal data that we call “sensitive data“, where the processing is generally prohibited, unless the controller can demonstrate a legal ground for the processing, such as the patient’s explicit consent (art. 9 §2 (a) GDPR, art. 4 al. 5 and 13 al. 1 of the Swiss DPA), the provision of medical services by a health professional tied by a secrecy obligation (art. 9 §2 (h) and 9 §3 of the GDPR) or private overriding interests (art. 13 al. 2 of the Swiss DPA). As one can read in the press almost everyday now, cyberattacks can happen, and a data breach may lead authorities to impose hefty fines, with 4% of worldwide annual turnover according to article 83 of the GDPR, although fines should remain a last resort in the sanction mechanism applied by the authorities. I wrote a note in this article about the envisaged approach with fines and sanction pursuant to the GDPR.

In addition, the doctor would also have to require the patient’s prior explicit consent before sharing, or allowing any third party to access, any sensitive data . See my previous note on recommendations for outsourcing in the context of medical billing for healthcare professionnals.

There are many other obligations under these regulations, which this article does not intend to cover.

________________________________

CONCLUSION

This FDA approval sounds like a very good “signal” to pharmaceutical companies developing connected drugs and advanced digital life science technologies, mHealth and medical devices.  This can improve the life of many patients, while saving costs and improving efficiencies in the treatment.

There is no need for scaremongering. However, remaining careful using the device for the purpose of the treatment, informing the patient and gathering explicit consent, processing only the data that is necessary for the purpose of the treatment, working with ethics and respect for the individual, especially if these patients have a reduced of discernment, are some good steps to ensure the individual’s privacy.

_____________________

To read more on this topic:

  • Mittelstadt, Brent, Ben Fairweather, Mark Shaw and Neil McBride. “The Ethical Implications of Personal Health Monitoring.” IJT 5.2 (2014): 37-60.Web.4Feb.2018.doi:10.4018/ijt.2014070104.
  • Mittelstadt, B., Fairweather, N.B., McBride, N., Shaw, M., 2011. Ethical Issues of Personal Health Monitoring: A Literature Review, in: ETHICOMP 2011 Conference Proceedings, ETHICOMP 2011, Sheffield, UK.
  • Elin Palm, Anders Nordgren, Marcel Verweij and Göran Collste, Ethically Sound Technology? Guidelines for Interactive Ethical Assessment of Personal Health Monitoring, 2013, Interdisciplinary Assessment of Personal Health Monitoring, 105-114.
  • Nordgren, Anders. (2013). Privacy by Design in Personal Health Monitoring. Health care analysis : HCA : journal of health philosophy and policy. 23. . 10.1007/s10728-013-0262-3.
  • Data protection and privacy in connected health, an article from a blog for research and innovation relating to emerging technologies.
  • Information notice  from “Otsuka Pharmaceutical”, the manufacturer of Abilify Mycite.

By Gabriel Avigdor | NTIC.ch

Prescription support software are considered as medical device

Prescription support software is considered as medical device

On 7 December 2017, the European Court of Justice (‘ECJ’) made an important ruling in the French case SNITEM and Philips vs Premier Ministre des Affaires sociales et de la Santé (Case C-329/16). The Court followed its general advocate advice, who issued a non-binding recommendation on 28 June 2017, and defined for the first time under what conditions should medical software (standalone software) be qualified as a medical device pursuant to Directive 93/42/EEC on medical device.

In this decision, the ECJ considers that “software, of which at least one of the functions makes it possible to use patient-specific data for the purposes, inter alia, of detecting contraindications, drug interactions and excessive doses, is, in respect of that function, a medical device within the meaning of those provisions, even if that software does not act directly in or on the human body”. Therefore, software of which specific functions do not have a medical purpose, are not medical device and are out of the scope of the Directive.

__________________

CE marking is sufficient

The Court adds that once the software bears CE marking, a national authority cannot request the software developer to proceed to an additional requirement such as another certification, as CE marking is sufficient.

In this French case, a decree contained an obligation to get a specific certification for prescription support software according to art. L. 161-38 of the French Code of Social Security. The French authority maintained its position that such software cannot be considered as medical device and therefore, would require this specific certification. WRONG, says the ECJ who confirmed that the clear intention of Philips to use this software in the context of healthcare, and for medical use, makes the functions of this software a medical device. Certications issued by the “Haute Autorité de Santé” (‘HAS’) were compulsory and now are now anymore. Even more, the decree will certainly be either cancelled or amended after this ruling.

This is an important decision for the medical software industry and for innovation in that sector to place them on the EU market (and also in Switzerland), as ECJ clarifies that although it remains compulsorily to “bear the CE marking of conformity when it is placed on the market. Once the marking has been obtained, the product, having regard to that function, may be placed on the market and circulate freely in the European Union without having to undergo any additional procedure, such as a new certification”.

This EU ruling is a lightening in the process which will benefit the industry by save time and money when putting medical software on the market. This clarification allows companies to avoid engaging costs as compliance as a measure of prevention. Legally speaking, there may be a possibility for companies that are in the process of getting their medical software certified to stop the process, or even claim for reimbursement if the decree is cancelled or modified and becomes illegal as a result of the ECJ ruling. In addition, it is likely that this decision may have an impact in other Member States of the EU, which would also be transposable, not only for prescription support software, but also for other medical software, or mobile medical Apps.

__________________

Scope of this decision

What is the scope of this decision?

Firstly, this decision applies clearly to prescription support software, but not only. The the ECJ provided criteria that are broad enough for applying to other medical software if the objective pursues a specifically medical objective. This ruling may be applicable by analogy to all medical software with a medical objective, even with no interaction in or on the human body. It is however necessary to proceed to a specific analysis on a case by case basis for each functionality of the medical software or the mobile medical App.

Secondly, this decision also applies to hospitals developing medical software, as these institutions can be software developers even with no commercialisation, as though they are responsible for first placing on the market. It is therefore necessary for hospitals developing medical software or Apps to assess whether it requires complying with the EU medical device Directive.

From a geographic point of view, even if the decision comes from a European authority, it applies to Switzerland, with automatic recognition of CE marking thank to the international convention on mutual recognition in relation to conformity assessment dated 2002 with EU.

Finally, the fact that this ruling is based on the Directive 93/42/EEC will remain valid with its replacement by the EU Regulation 2017/745 on medical device that is going to replace as of 26 May 2020.

__________________

In deeper details – Background of the dispute

The dispute arose in relation to “Intellispace Critical Care and Anesthesia” (ICCA”) software developed by Philips, as this company focuses now into the software and IT projects in relation to the healthcare sector. The functions of the prescription support software makes it possible to use patient-specific data for the purposes, inter alia, of detecting contraindications, drug interactions and excessive doses.

The dispute opposed the national syndicate of medical technological industries (SNITEM in French) and Philips on one hand, against the French Minister of Social and Health Affairs on the other hand. Based on a local decree which imposes prescription support software companies to get a specific certification, the French authority argued that: (a) Philips’ software was not a medical device, (b) requires getting the additional specific certification for prescription support software, and therefore (c) cannot freely put into the market its software on the sole basis of the CE marking.

On the other hand, Philips argued that, its software is a medical device and “the requirement to adapt software to technical standards constitutes a measure having equivalent effect to quantitative restrictions on imports which, overlapping with the certification obligation for medical devices laid down in Directive 93/42, which is applicable to software, does not meet the requirements of necessity and proportionality”.

In other words, Philips claimed that CE marking was sufficient. Philips won the case on this question.

__________________

Challenges of this case and first precedent

The central question of this case is not the certification itself, but the question to know if ICCA software is be considered as a medical device or not in accordance with Directive 93/42/EEC on medical device. This question may appear somehow unoriginal. It is not. If a software is considered as a medical device, regardless of how it is classified, will need to comply with the EU medical device Directive requirements. In the German case Brain Products GmbH vs BioSemi VOF, the ECJ only provided an indirect reference to the criteria for software as a medical device (‘SaaMD’) qualification.  In that case, the ECJ mentioned that fitness Apps would probably not meet the definition of medical device, while software monitoring humain brain activity would.

The Philips case also refers to the MEDDEV 2.1/6 (Commission Guidelines on the qualification and classification of stand-alone software used in healthcare within the regulatory framework of medical devices) as explained by the advocate general in its recommendations dated 28 June 2017.

__________________

CONDITIONS AND EXAMPLES

ECJ reminds that it is not sufficient to use the software in a medical context; it is also necessary that the intended purpose, defined by the manufacturer, is specifically medical. Therefore, two cumulative conditions are necessary to consider a health-related software as a medical device, which are relating respectively to the objective pursued and the action resulting therefrom.

  1. Objective pursued: a medical device must be intended by the manufacturer for use in humans for the purposes, in particular, of the diagnosis, prevention, monitoring, treatment or alleviation of a disease, and the diagnosis, monitoring, treatment, alleviation of or compensation for an injury or handicap;
  2. Action resulting therefrom: ECJ interprets the Directive 93/42/EEC and considers that “although that provision provides that the main action of the medical device ‘in or on the human body’ cannot be obtained exclusively by pharmacological or immunological means, or by metabolism, it does not require such a device to act directly in or on the human body”.

Interesting to notice that, according to the ECJ’s argumentation, the second condition is not decisive. On the contrary, requiring that the action resulting from the device shall produce an effect or works directly in or on the body would mean that software with no effect on the body would not be subject to the Directive, which would be contrary to the intent of the EU legislature.

In the case of prescription support software, the European Court of Justice states (§25) that functions of such software: “that cross-references patient-specific data with the drugs that the doctor is contemplating prescribing, and is thus able to provide the doctor, in an automated manner, with an analysis intended to detect, in particular, possible contraindications, drug interactions and excessive dosages, is used for the purpose of prevention, monitoring, treatment or alleviation of a disease, and therefore pursues a specifically medical objective, making it a medical device within the meaning of Article 1(2)(a) of Directive 93/42”.

SaaMD or not? Examples:

The ECJ provides examples of prescription support software that may or may not be used as a medical device:

  • SaaMD: function that permits the use of data specific to a patient to help his doctor issue his prescription, in particular by detecting contraindications, drug interactions and excessive doses, even though it does not itself act in or on the human body;
  • Not a SaaMD: software for general purposes, when used in a healthcare setting, is not a medical device;
  • Not a SaaMD: software intended to indicate the contraindications mentioned by the manufacturer of that drug in its instructions for use;
  • Not a SaaMD: software that, while intended for use in a medical context, has the sole purpose of archiving, collecting and transmitting data, like patient medical data storage software, the function of which is limited to indicating to the doctor providing treatment the name of the generic drug associated with the one he plans to prescribe.

__________________

OUTCOME OF THIS RULING

After this ruling, there are at least three main take aways:

  • First, medical device regulation applies to functionalities of medical software where two cumulative conditions are met (medical purpose pursued by the manufacturer and the action pursued therefrom), with a focus on the first condition;
  • Second, such regulation only applies to functions of the software which are coded in a way to produce such effect, but do not apply to the source code in its entirety, even if the software has no effect in or on the human body;
  • Third, where the software, for that particular section of the source code, bears CE marking, it benefits from freedom of circulation of goods within the EU [and therefore in Switzerland as well] and can be placed on the market without any further certification or requirement.

__________________

What other consequences for software as a medical device?

When a software is qualified as a medical device, the manufacturer will have to assess its classification based on the degree of risk for the human body (classes from I to III) and will have to comply with its duties to declare Class I software to the regulation authority (national authorities in the EU and Swissmedic in Switzerland). For classes IIa, IIb and class III software, obligations are stricter.

Depending on the conditions that are applicable, there is a materiovigilance requirement (pre-market approval and then post-market surveillance/vigilance) by the manufacturer, as well as product security, quality control and quality assurance management, as well as other standards (such as ISO). For products coming from the EU, once they bear the CE marking, they benefit from the freedom of circulation in Switzerland and vice versa without any pre-market approval.

All standards that apply to medical devices, depending on the degree of risk, but also obligations, restrictions and potential sanctions of the authorities, will mutatis mutandis apply to software as a medical device. This is necessary to guarantee free circulation within the EU of safe and secure products for consumers or patient health.

Want to know more?

Swiss Digital Day: 21-11-2017

The first Swiss Digital Day happens today 21 November 2017 at several main points, such as Geneva Gare Cornavin and Zurich mainstation. It can be followed via the traditional social media under #Digitalday!

__________________

Inform, entertain and instigate discussions

This great event led by the association “digitalswitzerland” is the first Swiss national digital day and aims to make Switzerland a “leading digital innovation hub, worldwide”, according to its founders.

Indeed, Switzerland not only is a country of innovation, but also of innovators with a huge number of startups and a creative mindset. The Global Entrepreneurship Index (GEI), which measures the quality and dynamics of entrepreneurship ecosystems at a national and regional level, ranked Switzerland eighth according to a 2016 survey!

Switzerland has all the keys to raise the bar even higher to empower itself and remain a pioneer in Xtechs (any tech) whether disruptive of a global reference for the digital age! We can make the difference in adopting a different approach to digital. The Swiss tradition of “waiting for others to make mistakes” is outdated in the digital age. Both private and public sectors should not be afraid to innovate.

We know that the power of the Swiss expertise, values and tradition is an asset. Let’s take the benefit of this worldwide uncontested reputation for developping a digital Swissness!

If you missed this unique event covered by Swiss medias and many other stakeholders, have a look at #digitalday on social media.

Share your thoughts and be creative, innovative, let’s empower the Swiss digital potential!

#Digitalday #innovation #legaltech

Outsourcing medical billing: a matter of transparency

What is required when outsourcing medical invoices to a third party?

_______________________________________________

In healthcare, it is frequent for medical professionals and health institutions to outsource medical billing to a third party. There are many financial and practical advantages to subcontract such service. First, outsourcing can increase efficiency, by reducing the cost of performing these kinds of tasks by the employees. Therefore, it saves work spaces and it is cost-effective, as the service is provided by experts within a company specialized in this area. Second, the responsibility and the costs for investing in this service, the employees’ management, staff training and keeping these skills up to date, are borne by the third party. Finally, one can expect regular reporting services and cooperation from the third party as part of the deal.

Where outsourcing contains many advantages, medical billing must comply with legal obligations, in particular with medical secrecy and data protection regulations, especially if the third party wishes to use the data for another purpose than medical billing. This would be the case if the personal health-related data are used for the supplier’s benefit (such as creating its own creditors and debtors database), or for the benefit of third parties (e.g.: selling the data to insurance companies).

Transferring health data of patients to a third party can infringe medical secrecy and data protection regulations. If the data are not used for the same purpose as for medical invoicing, the Swiss Criminal code (art. 321), the Swiss Federal Data Protection Act (DPA), and cantonal laws protect the medical secrecy by prohibiting undue disclosure without express consent of the patient.

Infringements observed by the Swiss Federal Commissioner

_______________________________________________

The Federal Data Protection and Information Commissioner (FDPIC) recently osbserved that third parties specialized in medical billing are using health data of patients to:

  • create their own database with individual’s solvency to categorize them; and
  • sell the data to third parties (such as health insurances).

According the FDPIC, healthcare professionals must reinforce their obligation to comply with transparency, which he states as follows:

Where healthcare professionals outsource medical billing services to third parties, they shall remain precise and draw attention of the individuals in a clear manner to where and to whom the data would be transferred, and for what purpose the supplier may process such data. This includes in particular using such health-related data to create unrelated databases and potential sales to third parties. In order to comply with this obligation, the healthcare professionals must get the individuals’ express consent“.

Medical secrecy and explicit consent

From a legal perspective, medical personal data – meaning health-related data from an identified or an identifiable individual – are sensitive data. This special category of personal data requires to get the patient’s explicit consent before the processing (art. 4 § 5 DPA), in writing , and before a transfer to a third party for another purpose than for medical invoicing. Therefore, it would be illegal to transfer and use of such data for another purpose without a valid written consent.

This practice complies with both art. 321 of the Swiss Criminal code and art. 10a § 1 let. b of the DPA to the extent the owner of the secret has released the health professional from the medical secrecy.

How do I draft my privacy clause in an outsourcing contract?

_______________________________________________

Among the other contract clauses which are specific to the outsourcing agreement, the contract should at least contain the following:

For outsourcing in Switzerland:

  • a reference to the relevant DPA provisions;
  • a warranty from the billing company to comply with the DPA provisions;
  • a warranty of fulfilment of data protection claims of data subjects;
  • the prior consent of the data controller (health professionals) if the data processor decides to subcontract the service;
  • describe the purpose for the processing of the data;
  • an obligation for the employees, auxiliary personnel, freelancers etc. of the processor to comply with the DPA provisions;
  • an obligation for the data processor to comply with data security obligations;

For cross-border transfers to the third party:

  • If permitted by national law to transfer to a third party based in another country, include a provision to regulate cross-border transfers. If personal data are processed (accessed or transferred) in a country without a sufficient protection level for the processing, the data protection clause shall at least include:
    • an obligation to enter into standard contractual clauses, such as the C2P EU model clauses (or privacy shield, or Swiss transborder data flow agreement);
    • an obligation for the data processor to enter into such standard model clauses with its affiliates located in countries without an adequate protection level;
    • an obligation or the data processor to inform the data controller prior the transfer if the data are being subcontracted, including a right to object, and provide information to the controller about the subprocessors (identity, location) and engage the subprocessor with a contract containing the same level of contractual obligations.
  • For the Swiss Federal commissioner, Swiss Doctor should not allow a third party outside Switzerland to access medical records. If so, the Doctor may infringe medical secrecy which is protected by the Swiss Criminal code and by the DPA.

Practical recommendations

_______________________________________________

According to the FDPIC, it is not sufficient to inform the patient of such processing somewhere in the medical office, or a waiting room. Nor would it be sufficient to add a clause in small letters in a medical consent form. To comply with transparency, the patient shall receive a proper information to allow – or not – the processing on the basis of a written consent. The patient shall do this without any pressure of any kind.

This short note of the FDPIC reinforces the principle of transparency of the processing.

For the patients

This memo is a call for reinforcement of transparency in the healthcare sector. It explains that more supervision will occur in the future in that particular area to protect the individuals’ right to privacy, and from an undue processing when third parties wish to use the data for their own benefit.

As consent is required, the patient may withdraw its consent at any time. In such event, healthcare professionals and any third party using the data will have to stop using them and potentially delete them to comply with the patient’s request.

For healthcare professionals and hospitals

The principle of transparency, which comes from privacy regulations is not new. It is protected by the non-disclosure obligation for healthcare professionals relating to medical secrecy. But even with the consent to disclose medical information, privacy regulations do not allow anyone to use any personal data for whatever purpose. It would be a breach of the DPA and the processing would become illegal.

In practice, doctors and hospitals shall duly inform the patient to allow him/her to validly consent to sharing medical information for other purposes than for medical billing.

The service provider being a data processor, it has to comply with all the data controller (doctors and healthcare professionals) instructions and requirements, and is responsible for the processing, and to comply with the DPA.

To remain cautious, heathcare professionals should ensure that:

with regard to the service provider:

  • it does not use the data for other purposes than for medical billing;
  • it will comply with privacy regulations, as well as medical secrecy, as the service provider is not bound by medical secrecy;
  • include a paragraph for get the data back at any time, at no costs;
  • for cloud computing purposes, use only service providers based in Switzerland, and draft a contractual clause to prohibit any transfer of such data to a subcontractor or a third party outside Switzerland

with regard to the patient:

  • update the consent forms and add a clear clause – separated from medical related acts – to draw the patient’s attention that the processing may be done for other purposes than medical being (and explain which ones);
  • if the data may be used for other purposes than for medical billing:
    • get the consent after having duly informed the patient and before to process the data; or
    • inform the patient of such transfer in order for the patient to give or withdraw its consent on the processing.

For service providers

The Commissioner has not given its opinion on the supplier’s civil responsibility towards the patient for undue processing, or medical secrecy infringement, or both.

In order to protect the service provider for using the data for other purposes than medical billing, it may perform the following:

  • anonymize the data, whichever it will use the data for its own use or to sell the data to third parties. In this case, medical secrecy and privacy laws will not apply;
  • clarify with healthcare professionals for what other purposes it wishes to use the data;
  • request healthcare professionals to ensure, in the outsourcing agreement, that the patient has been informed of the processing validly given its consent to the processing;
  • include a specific exclusion of liability in case of a third party claim (for medical secrecy of privacy infringement);
  • add an indemnification clause for losses it may incur as a result of the breach of privacy laws or medical secrecy.

To go further, see the following notes on the website of the Swiss Federal Commissioner:

  • This note in French, German or Italian on outsourcing in the context of healthcare
  • This note in French, German or Italian on the use of service providers for keeping medical records in the cloud
  • This note in French, German or Italian on security in medical offices
  • Guide on processing of personal data in the context of healthcare

Gabriel Avigdor | NTIC.ch

Gabriel Avigdor, avocat PME magazine

Lawyers 4.0: the new generation of tech lawyers

Swiss Technology lawyers 4.0

A new generation of Swiss technology lawyers has arrived to answer the challenges which faces the society in this 4th industrial revolution”, says the Swiss local journal “PME Magazine”.

This article dated 28 June 2017 provides a nice presentation of the new generation of geek lawyers which are specialized in the field of technology. I am very honoured and proud to be part of this article, which draws a nice picture, together with my three colleagues: Nicolas Capt, Sylvain Metille and François Charlet.

You can access the full version of this article here in French. Alternatively, you can access the online version here.

Have a nice reading.

Drone

Drone regulation : compared case study under US and Swiss laws !

INTRODUCTION

What is a drone and what does it do? Drones are those little guided quadcopters (also called FPV drones for ‘First Person View’) that we can find in the FNAC or in Xtreme sport videos on Youtube. They can be used for civil (private, commercial or humanitarian) or military purposes. We do not realize that they will invade our low sky and replace lots of current tools. As examples, drones can be used for:

  • Delivery services for food or commercial and private mail: With its Prime Air program, Amazon announced an estimated time of delivery of max 30 minutes. The Swiss e-commerce company Qoqa has taken the lead on Swiss market of delivery by drones with a test phase for the first time in Switzerland called FlypaQ.
  • Mapping and modelling like the Swiss company Pix4D with its mapping software that is able to create 3D modelling from 2D pictures.
  • Fun and hobbies, like personal video recording, sport even and cinema. Autonomous drones used during sport activities are very popular as shown by the French start-up Hexo+. In Hollywood, the FAA authorized film producers to use drones for film shooting. Cameramen are being replaced by these drones to record scenes in the air or for car chase, which offers original angles of view. Skyfall, the Wolf of Wall Street or Harry Potter and the secret chamber contain scenes that have been shot via such drones.
  • Observation, surveillance private or public, like locating or tracking people being pursued or surveillance of events by the police for Euro2016.
  • For humanitarian or rescue purposes especially in area difficult to access or for sending food, medics, give logistics support when a natural disaster happens, etc.
  • For military purposes, to attack specific targets, to defend, track or identify, spy or watch civil zones …

 

Ideas are not missing. From an economical point of view, there is a huge market growing up for the manufacturing, repair industry and for a bigger part software companies providing specialized software and mobile applications.

Disadvantages and risks. Potential often rhymes with risks. One can argue that not everyone owns a beautiful villa with a garden and a playground where the drone can land easily to deliver a new pair of shoes like in the sympathetic, but naive trailer of Prime Air drones of Amazon…How to deal with the lambda citizens living in buildings in the cities? Will there be landing points in the city to avoid a delivered package to be stolen? In addition, with 4K UHD cameras, video surveillance will cause problems related to privacy for individuals. The Swiss Federal Data Protection Commissioner (the Swiss Commissioner), published a note on this particular matter. Furthermore, as drones are either guided or autonomous flying vehicles with a certain weight, they may collide with flying objects (or animal) or with people on the ground. Liability issues will then occur as incident risks are real. This has already been demonstrated by the recent crash of a drone with a passenger aeroplane from the company British Airways just before landing at London Heathrow airport on April 18th, 2016. From a noice perspective, it would be easy to imagine that a sky overloaded with drones would cause damage to the environment as well as to the residents. Animal welfare organizations will likely mobilize for the cause. Even worse, one can imagine drones to be hijacked, hacked, but also used for terrorist purposes. Maybe there is here a threat that shall not be underestimated…

Future will tell us.

____________________________

PART I

DRONE REGULATION IN THE USA – CASE STUDY

Producers of TV series are very creative to elaborate original and fun scenarios related to new technologies, especially when interpretation of the law remains uncertain. One of the latest episodes (S07e18) of the excellent TV show The Good Wife, created by Ridley Scott, is a story about a surveillance drone flying above a neighbourhood recording the area for potential crime that may be committed, which disturbs one of the residents. The litigation is divided in three acts like a case study for law students or cases for bar admission exam.

ACTE 1. The owner of the drone is a private organism that seeks to record acts of crime in the neighbourhood. The drone prototype flies several times a day and randomly over the houses, recording the streets and the houses, which means people that may be inside or outside their house. The fact is that on resident isn’t happy because, as a therapist, he practices at home and his patients are filmed from the air when they come for an appointment. The therapist takes legal action against the owner of the drone for violation of his private life, especially because the drone can film people that even appear through the windows of the house that have not given their consent. He also considers the drone responsible for a loss of patients and claim for compensation damages in an amount of USD 300,000 with a prohibition for the drone to fly again.

Arguments: The therapist alleges a violation of his private life based on the common law principle of “intrusion upon seclusion“, but loses the trial. Under first amendment of the US constitution, the right for the owner of the drone and the interest of all other neighbours to prevent acts of crimes by air surveillance wins against the privacy rights and the drone can fly!

______________________________________

FLY AGAIN OVER MY PROPERTY AND I WILL SHOOT YOUR DRONE !

ACTE 2. The drone continues to fly over the houses and the drone camera record the therapist taking his shotgun and destroys the drone while flying over his property. This time, the owner of the drone takes legal action against the therapist and asks for compensatory damages to get reimbursed of the value of the drone, which is an USD 80,000 prototype. In addition, the owner claims for USD 10,000 punitive damages as well as a prohibition for the therapist to shoot any drone that would fly over the houses.

Arguments: The therapist alleges that he shot the drone because he felt threatened. He argues that the drone was shot to repel a potential attack. His counsellors plead the “Castle doctrine“, created in 1628, which is a common law principle for legitimate defence specific to the property. Under this doctrine, a landlord can repel an imminent attack when there is a legitimate threat of an intrusion in his property or the house. As the judge considers that this situation does not constitute a reasonable fear/threat, he requires the lawyers to prove it. Therefore, the counsellors call a drone expert, who presents to the Court a video with civil and military drones showing that it is almost impossible to make the difference between civil drones and combat drones. We can also see that drone technology allows to capture infrared or heat detection images and that some other drones can feature connected technologies that can hack a computer from the air and can steal the landlord’s personal data. In reference to the castle doctrine, the expert concludes that a drone can be an intruder in the house without physically penetrating it resulting in a violation of the therapist’s property and privacy.

Despite those efforts, the drone owner wins this second act. The recording shows that, at the moment the therapist shot the drone, it was not flying in a stationary mode, but rather flying away the propertym which means he was “retreating”. In such case, the castle doctrine is not applicable to retreating because it is strictly prohibited to shoot in the back…

____________________________

THE SKY IS ALSO MY PROPERTY, RIGHT?

ACTE 3. The final act intend to solve altitude issues related to unmanned aircraft systems. Basically, the question is to know whether the drone was still flying in the jurisdiction of the FAA (Federal Aviation Administration) when flying over the property of the therapist or not. As the drone was shot at a 200 feet altitude (60m), the Court must determine whether the federal rules of FAA still apply or if the case is governed by the rules of private property.

Arguments: The chief legal counsel of the FAA (from the enforcement and compliance division) is called to inform the Court whether it is legal or not to shoot an unmanned aircraft in this area of space. The legal counsel explains that between 0 and 500 feet (150m), there is a zone  called “Classe G” that does not fall under the FAA’s jurisdiction.  According to the therapist’s lawyers, it would be illegal to shoot a drone over 500 feet, but totally legal under.

The attorney of the owner of the drone, plead the US vs Causby case. In this case, military planes from the military airport where making a lot of noise in addition to flies over Mr Causby’s property. This situation caused a severe damage to Mr Causby’s, which forced him to abandon his business. Actually, the planes were flying at an altitude of 83 feet (25m) above the farm which led the chicken to jump over the wall killing themselves. This case refers to an old Roman law principle “Usque ad sideras et usque ad inferos”  which inspired the common law principle of “from the depths to the heavens” related to vertical property. In Causby’s case, which he won, the limit of the vertical property was set at 83 feet. Thus, 200 feet (60m) is above 83 feet, which means the therapist was not entitled to shoot the drone that wasn’t flying over the space of his property. On that question, the lawyer of the FAA considers that between 83 and 500 feet, the regulation never said anything. The judge then considers that, in this case, the law is not adapted to technologies and rules in favour of the owner of the drone confirming Causby’s case.

This funny episode proves that, at least in the USA, one can play with the law and imagine scenarios that may be solved in such manner. The solution of such litigation may be based on very old case law related to airplanes frightening chicken, which may be inappropriate, but applicable to drones…

This first part only offers a summary of a TV show for further discussions. In no event shall this constitute a legal opinion under US law. For further information under US Law related to drones, this legal blog provides very detailed information and is only dedicated to the applicable regulation and rules of drones in the USA.

____________________________

PART II

DRONE REGULATION IN SWITZERLAND

What is the regulation in Switzerland and how would a Swiss Court rule this case ?

In Switzerland, unmanned aircrafts systems are regulated by the Federal Office of civil aviation (FOCA). It is governed by the Swiss Federal Act related to Aviation (LA) and the Federal Ordinance about special category aircrafts (OACS). “Air rules” also supplements this regulation with EU law related to the maximum flying altitude. Because of the developments of the civil drones market, FOCA recently amended its Ordinance and gave some guidance. From a legal perspective, drones are mostly remotely piloted aerial vehicles. They are de jure aircraft models, which corresponds to Small Unmanned aircraft Systems (sUAS) in the USA. Up to a weight of 30 kg these aerial vehicles can basically be operated without a special permission under the condition that the pilot keeps a permanent eye contact with the flying object (art. 17 OACS). Under those rules, drones are not allowed to fly above gatherings of people. Any exception to these principles requires an authorization from the FOCA, that can be required through this page, especially for drones that are operated without any eye contact.

For further information, visit the website of the FOCA or AirShoot suisse.

____________________________

HOW TO APPLY US CASES UNDER SWISS LAW ? 

It seems interesting to wonder, from a theoretical point of view, how the fictive litigation of Ridley Scott would have turned if it had happened in Switzerland. Of course, US trials are extremely different from EU countries and are based on common law principles (Anglo-saxon influence) that differ a lot from civil law principles (Roman law influence) .

ACTE 1 – Private surveillance  from the air. The first act basically raises two questions: how can a citizen use a drone for private surveillance and to what extend can the landlord claim for damages to the owner of the drone for loss of customers.

Arguments : Drone surveillance is related to both aviation rules and right to privacy or right to publicity (art. 28 of the Swiss civil Code and Data protection Act). With autonomous unmanned aircraft flying without constant visual eye contact from the pilot, the owner needs a permit from the FOCA. It is likely that for privacy rules or publicity rules, as well as security of the residents and noise pollution, no permit would be delivered for an autonomous, frequent and random fly over a residential neighbourhood.  It would be a case by case question that may only be decided by the FOCA. A surveillance drone records images from the air on the private and public domain. Video surveillance on the public domain is not allowed by private individuals or companies without concluding an agreement with the local authorities. According to the Swiss Commissioner, such surveillance on the public domain is generally considered as disproportionate and prohibited, unless the area filmed on the public domain is very small. Because the rights to privacy of passers-by would be violated, such surveillance would probably be illegal as it is the role of the police to prevent acts of crimes and to have jurisdiction in this field.

____________________________

CONSENT THAT HITS THE  NAIL ON THE HEAD

Regarding drone videosurveillance on the private domain, the Swiss Commissioner published a memento related to surveillance by private individuals. In summary, if a person cannot be identified, especially if faces or licence plates are blurred, the Data protection Act will not apply. Other questions would raise such as neighbourhood law in relation to excessive noise imissions (art. 684 al. 2 of the Swiss Civil Code). As the purpose of the surveillance is to know the author of the crime, the faces would not be blurred, and this images would be stored, used, published or even sent to the police. To be legal, every filmed person should consent to this recording (art. 13 Privacy Act) after having been informed (art. 4 al. 5 privacy Act) of the surveillance. It could be done through warning signs with detail information of the owner. In a recent decision 4A_576/2015 of March 29th, 2016, the Swiss Supreme Court considers that even inside a building, one single tenant can refuse to be filmed and can require the landlord to withdraw all the cameras of the building. In the Ridley Scott case, there may be other less invasive ways for the owner of the drone to prevent acts of crimes. The answer would certainly be different for surveillance of a commercial property with no passers-by and with high security risks.

Except neighbourhood issues, the liability of the owner of the drone for loss of customers is interesting. This is a case of civil liability in the form of an economical damage caused by a third party to the customers of a resident with a decline in turnover. There is no contract between the parties, which means that basic rules of tortious liability. Such trial would not be easy for the neighbour to win especially if the drone is entitled to fly. If it is not, the therapist must prove that civil liability rules have been violated according to article 41 of the Swiss Obligation Code. He would need to prove that (1) he has suffered a prejudice (decline of turnover), (2) in “natural and adequate causal relation” with the fly of the drone over the houses, (3) that the owner of the drone violated a specific article of the law (legal principles or articles such as violation of the Data Privacy Act) and (4) that the owner of the drone committed a fault (wisful misconduct or negligence). If these four conditions are met and if the therapist can quantify the amount to claim, he would be entitled to claim for damages…

____________________________

GIVE ME MY GUN SO THAT I CAN SHOOT THIS GODDAMN DRONE ! 

ACTE 2 – Shooting the drone. Weapons regulation is very different in Switzerland compared to the USA. Very far from the second Amendment of the US Constitution that give to every US citizen the right to wear a gun, Switzerland prohibits any acquisition, possession or use of automatic weapons (art. 5 al. 1 to 3 of the Swiss Federal Act related to weapons). The fact that one can buy a gun if he holds a licence (art. 8 LArm), does not mean that he would be allowed to have free use of it. If someone shot from his garden like the therapist did, the neighbours would very likely report such act by calling the police or to criminal authorities for fraud to the Swiss weapons Act, or to have taken a risk for the neighbours life or physical integrity in case the drone crashes. The issue would be similar if the therapist destroys the drone without any weapons resulting in a risky zone. It would depend on the weight, the height and the place where the drone could land or crash in case of an accident. If nobody is hurt and no risk was created, the owner of the drone could only claim for reimbursement of the drone if the drone was flying illegally over the therapist’s property.

____________________________

I SAY: THERE IS A DRONE FLYING OVER MY GRASS !

ACTE 3 – From the depths to the heavens. Switzerland abandoned since a long time the Roman Law principle under which a landlord can repel any threat or disturbance to one’s property from the hell to the heaven, which meant regardless of the depths or the height. Jurisprudence related to article 667 al. 1 CC explains that a landlord can master aerial space and prevent or stop any misconduct from a third party in this space if it undermines peaceful use of the property. However, the Swiss Supreme Court declares, in a first case, that property right shall continue at least up to a height of 10m to 40m corresponding to a cable car passing over a constructed house or building. The Court also declared that it is illegal to fly at a low altitude in the nearings of a private airport without consent of the landlord who may be entitled to oppose. Therefore, a landlord is entitled to protect and defend himself against damages to his property from third parties, for example against noise disturbance at an altitude of 108m, but not  600m…

Argumentation : Given the mentioned jurisprudence, it is certain that property rules apply up to 40m, likely up to 108m, and unlikely with a doubts between 108m and 600m. In the Ridley Scot story, the drone was flying at 60m (200 feet) above the property of the therapist. Therefore, the drone would still be in its property and, to the extend that the fly caused a prejudice to the therapist, who must have a legal interest to exercice its rights against the owner of the drone.

____________________________

SEE YOU IN A CRIMINAL COURT !  BUT REALLY, BASED ON WHAT ?

From a criminal point of view, one can advice to file a complaint to the Prosecutor (district attorney) or the police based on a violation of domicile (unlawful entry). In Switzerland, this offence (art. 186 of the Swiss Penal Code) would be difficult to apply as it related to humans, entering a garden  closed with a fence. Thus, it is hard to fence off the sky…To know if an unmanned aircraft can imply to hold its owner as liable for for unlawful entry is questionable. Unmanned aircraft may cause injuries, but in this case no accident has occured. If someone is placed in a life-threatening position by the drone another offence could be questionable, but hardly applicable (art. 129 CP). Legitimate self-defence related to unlawful entry can apply. Under Article 15 CP, imminent attacks can be legally repelled, for example, against its property or if one’s individual freedom is violated. The therapist could also try to file a complaint for violation of the Swiss Data Protection Act (art. 34 et 35 LPD)…

CONCLUSION

If shooting a drone is forbidden in your country, well you may be forced to use on of these techniques :